SPECIAL MANAGEMENT SRL with registered office at via Revere 11, 20123 Milan - Italy (“us”, or “we”), is Data Controller in respect of your personal data with reference to Rosa Sarli. This Privacy Notice provides detailed information on the collection, processing and storage of your personal data operated by us. If you have any questions about this Privacy Notice, you can contact us via email@example.com .
Please read the following carefully to understand our practices regarding your personal data and how it will be treated.
- "Users": any person to whom we provide consultancy work to pursuant to the Contract.
- "personal data": any information concerning a person that makes that person identifiable.
- "Contract": the contract under which we provide consultancy work in favour of Users.
3. WHAT PERSONAL DATA WE COLLECT ABOUT YOU
We acquire, process and store the personal data of potential, current and previous Users and their respective parents as well as anyone exercising parental responsibility over the Users and, in any case, of anyone who consents to the processing of their personal data by us for the purposes set out in paragraph 8. Personal data which is submitted to us may include:
- names, surnames, places of birth, nationalities, social security numbers, addresses, email addresses, telephone numbers, Skype contacts or other videoconferencing platforms, static copy of identity documents and / or passports;
Other types of data acquired, processed and stored by us may include special category data such as:
- medical and health information, demographic information, any certified learning disabilities, any handicaps, the state of health, any insurance coverage, any criminal records, biometric data or ethnicity data.
Such special category data will only be acquired, processed and stored by us where we have your explicit consent.
If you contact us with a complaint or query, we may keep a record of any phone number used to call us as well as the correspondence and the period of time it took for us to deal with a query or any request you had. We may also record your levels of satisfaction with the services we have provided.
When you visit our website, we may also collect information from you automatically, for example by using cookies and other similar technologies. A cookie is a small file of letters and numbers that we may set on your device. This type of information may include the following:
- information about your device operating system and IP address;
- your login information;
- browser type and version; and
- information about your visit on our website, including URL, clickstream (i.e. your journey to, through and from our site), length of visits to certain pages, and page interaction information.
The cookies we use fall into the following categories:
- Session cookies: These allow our site to link your actions during a particular browser session. These expire each time you close your browser and do not remain on your device afterwards.
- Persistent cookies: These are stored on your device in between browser sessions. They allow your preferences or actions across the site to be remembered. These will remain on your device until they expire, or you delete them from your cache.
- Strictly necessary cookies: These cookies are essential for you to be able to navigate the site and use its features. Without these cookies, the services you have asked for could not be provided.
- Performance cookies: These cookies collect information about how you use our site, e.g. which pages you go to most often.
- Functionality cookies: These cookies allow the site to remember the choices you make (such as your user name, language, last action and search preferences) and provide enhanced, more personal features.
If you do not wish for cookies to be installed on your device, you can change the settings on your browser or device to reject cookies. For more information about how to reject cookies using your internet browser settings please consult the “Help” section of your internet browser (or alternatively visit http://www.aboutcookies.org). Please note that, if you do set your internet browser to reject cookies or otherwise withdraw your consent in relation to cookies, you may not be able to access all of the functions of the site.
4. METHODS OF PERSONAL DATA COLLECTION
We collect your personal data in various ways, including:
- when you contact us;
- by electronic and paper documentation, including contact emails, registration forms, contracts entered into with us, contact forms completed on our website or on other sites that collaborate with us, digital apps, social media, emails, paper letters, consent forms, via our website, invoices or accounting documents;
- by producing static copies of identity documents, passports or other personal documents required if necessary;
- by means of surveillance cameras installed in our premises or webcams;
- through third parties, such as contact persons, schools or professionals; and
- by means of publicly available resources.
5. LEGAL BASIS FOR PROCESSING
We will only process your personal data where we have a legal basis to do so. The legal basis will depend on the purposes for which we have collected and used your personal data. In almost every case the legal basis will be one of the following: - Consent: For example, where you have provided your consent to receive the services or other information (including marketing) from us. You can withdraw your consent at any time.
- Our legitimate business interests: Where it is necessary for us to understand our customers, promote our services and operate effectively, provided in each case that this is done in a legitimate way which does not unduly affect your privacy and other rights.
- Performance of a contract with you (or in order to take steps prior to entering into a contract with you): For example, where you have decided to engage our services and we need to use your contact details and payment information in order to provide the services to you.
- Compliance with law: Where we are subject to a legal obligation and need to use your personal data in order to comply with that obligation.
6. METHODS OF DATA PROCESSING
We process your personal data in accordance with the provisions of the GDPR. The processing will be carried out using automated, manual, paper-based methods and will take place using suitable tools to guarantee adequate security and confidentiality through internal procedures and security software that avoid the risk of loss, unauthorized access and accidental dissemination of the same.
7. DATA RETENTION
Your personal data may be kept by us for ten (10) years from the last activity carried out or in any case for all the time necessary to carry out the purposes referred to at paragraph 8 below. After this period, we will delete your personal data or may keep the data in anonymous form and for statistics.
The personal data will be stored on paper and computer media suitable for preventing or minimizing the risks i) of accidental destruction or loss of the personal data, ii) any unauthorized access, iii) a processing that does not comply with the purposes set out at paragraph 8 below or in any case not allowed or contrary to the consent given by you.
8. PURPOSE OF PROCESSING
We may process your personal data mainly for the purpose of carrying out consultancy work and all the other obligations referred to in the Contract.
9. WHERE WE STORE YOUR PERSONAL DATA
The personal data that we collect may be transferred to, and stored at, a destination outside the EU, including countries, which have less strict, or no data protection laws, when compared to those in the EU.
Whenever we transfer your information as described in the paragraph above, we will take steps which are reasonably necessary to ensure that adequate safeguards are in place to protect your personal information and to make sure it is treated securely and in accordance with this Privacy Notice. In these cases, we rely on approved data transfer mechanisms (such as standard contractual clauses) to ensure your information is subject to adequate safeguards in the recipient country. If you are located in the EU, you may contact us for a copy of the safeguards which we have put in place to protect your personal information and privacy rights in these circumstances.
10. YOUR RIGHTS
Under the GDPR, you have certain rights in relation to your personal data. These include rights to:
- access your personal data;
- request your personal data to be rectified, integrated and updated;
- request that your personal data be deleted;
- request data portability;
- request to object or limit the processing of your personal data; and
- lodge a complaint to the relevant data protection authority. We will handle any request to exercise your rights in accordance with applicable law and any relevant legal exemptions. If you wish to exercise any of these rights please contact us at firstname.lastname@example.org. As above, you have the right to complain to a data protection authority if you think we have processed your personal information in a manner which is unlawful or breaches your rights. If you have such concerns we request that you initially contact us (at email@example.com) so that we can investigate, and hopefully resolve, your concerns.
If you are a parent or guardian, you have the right to request information relating to you or the relevant User however we may require the consent of the Users themselves in the event that they are of an age for which it is possible to understand the implications of such a request. We will handle any such request in accordance with applicable law and any relevant legal exemptions.
We cannot disclose confidential information that is related to the purpose of providing education, examinations or providing examination papers to external entities or individuals. We are not authorized to disclose the confidential information of staff or tutors.
11. UPDATING THIS PRIVACY NOTICE AND CONTACTING US
We may update this Privacy Notice from time to time. Any substantial change that may affect you and the processing of your personal data will be notified on the website or through a specific newsletter. This Privacy Notice must be read in conjunction with our other policies and any contractual terms and conditions. Questions and comments regarding this Privacy Notice should be sent to: firstname.lastname@example.org.
This Privacy Notice was last updated in April 2021.